A cybersecurity company reports that in the lead-up to U.S. oil sanctions against Iran, a group of hackers linked to the Iranian government has launched a widespread campaign against several companies, including those in the energy sector in the Middle East. According to the Associated Press, the California-based cybersecurity firm FireEye states that this Iranian group is stealing computer data through phishing emails. FireEye emphasizes that the threats from these hackers have intensified ahead of the implementation of oil sanctions against Iran and suggests that these attacks may become more extensive with the enforcement of these sanctions. Following the U.S. withdrawal from the JCPOA, the first round of mainly financial sanctions against Iran was implemented on August 7 of this year. However, energy sector sanctions are set to take effect on October 31. These sanctions include restrictions on Iran's energy sector, including oil sanctions and transactions of foreign financial institutions with Iran's central bank. U.S. officials have accused Iran of preparing for 'cyber attacks.' Alistair Shepard, a manager at one of FireEye's subsidiaries, told the Associated Press that there is always concern regarding Iranian hackers, especially those influenced by geopolitical changes, that they may carry out destructive attacks. FireEye, which typically collaborates with various governments and large companies, identifies this group of Iranian hackers as APT33 and states that they have gained access to the computers of targeted companies by sending phishing emails regarding job opportunities. According to the company, these phishing emails have been sent to companies in the Middle East, North America, and Japan, with recipients including firms in the oil and gas, aviation, services, insurance, manufacturing, and education sectors. The report does not mention the names of these companies. FireEye claims to have been monitoring APT33 since 2013 and emphasizes that the group's activities have become more complex and advanced over the years. Mr. Shepard notes that Russian hackers operate in a much more sophisticated manner than these Iranian hackers, but he adds: 'This group [APT33] is very capable and can achieve its goals, including endangering government and private institutions and stealing data.' Concerns about 'cyber attacks' are prevalent among countries in the Gulf region. FireEye has added that these hackers use a type of malware that destroyed tens of thousands of computers in Saudi Arabia in 2012. The company refers to the 'Shamoon' malware that targeted Saudi oil company Aramco and a Qatari gas company named RasGas in 2012. This virus wiped all data from the hard drives of infected computers and displayed an image of the burning American flag on the monitor. A second version of this malware also infected Saudi government computers in 2016. FireEye emphasizes that at this stage, these hackers have only accessed information from these computers through phishing emails. The company claims to have clues indicating that this group is directed by the Iranian government, including the fact that these hackers use Persian and their working hours are from Saturday to Wednesday. Iran has not yet responded to these statements. In this context, concerns from the German domestic intelligence agency about Iran's cyber attack capabilities have been reported, and Facebook and Twitter announced the removal of hundreds of accounts linked to Iran. Iran has been accused of involvement in cyber attacks on the emails of British parliament members.
Warning About 'Iranian Hacker Attacks' Ahead of Oil Sanctions
A cybersecurity firm warns of increased Iranian hacking activities targeting companies in the energy sector ahead of upcoming U.S. oil sanctions. The group, identified as APT33, is using phishing emails to steal sensitive information. This escalation raises concerns about potential cyber threats in the region as geopolitical tensions rise.
👥 Key Players
⚡ Actions
📰 What Happened
Iranian hackers linked to the government launch cyber attacks on companies ahead of U.S. oil sanctions.
- APT33 attack companies in the energy sector
- FireEye announce companies in the Middle East, North America, and Japan
- Iran prepare cyber attacks
💡 Why It Matters
📚 Background
Iranian cyber activities are escalating in response to impending oil sanctions.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%